Logo GH

Whistleblower policy and personnel protection

1) Introduction and objectives

Whistleblowing is the foundation of corporate ethics and risk management. It creates a safe way for employees, contractors, partners and affiliates to report violations: corruption, fraud, AML/sanctions, violations of responsible play, data security, harassment, conflict of interest, manipulation of reporting, etc. Policy goals: (1) early detection of violations, (2) protection of reporting, (3) transparent and fair investigation, (4) prevention of reprisals.

2) Key principles

Zero tolerance to reprisals. Any form of pressure, lowering, dismissal, "freezing" bonuses, threats are prohibited.
Confidentiality and, if possible, anonymity. The identity of the informant is disclosed only by legal necessity and with an access protocol.
Independence of investigation. Conflicting parties and their managers are excluded.
Timeliness and proportionality. The terms are fixed by the SLA, the measures are commensurate with the risk.
Integrity protection. A bona fide message is protected, even if the fact is not confirmed.
Lack of immunizing effect for abuse. Knowingly false denunciations are disciplinary responsibility.

3) Scope

Internal employees (staff/contract).
Contractors, consultants, affiliates, support agents, game/payment providers.
Job candidates (reports of recruiting violations).
Former employees (limited time after dismissal, recommended ≥ 12 months).

4) What and where to report (categories)

Finance/fraud: fictitious accounts, kickbacks, "drawing" metrics, bonus abuse by staff.
Compliance: AML/KYC violations, sanctions, forgery of documents, illegal gambling in prohibited geo.
InfoBase/data: leaks, backdoors, KMS bypass, log manipulation.
Ethics/HR: harassment, discrimination, bullying, conflict of interest.
Game honesty: RTP/RNG manipulation, unscrupulous promos.
Occupational Health/Safety: Health Hazards, H&S Violations.

5) Message channels (minimum set)

1. External burning line (24/7, independent operator): web form, telephone, e-mail; support for anonymity and multilingualism.
2. Internal portal/bot (SSO, but anonymous window option).
3. DPO/SRO/Compliance Officer - personal mailbox.
4. Physical trust box (for offline locations).
5. The right of external communication to regulators/ombudsmen if internal channels have not worked or there is a risk of reprisals.

Channel requirements: encryption, audit log, status tracking, SLA timers, deanonymization protection.

6) Timing and SLA (recommended standard)

T + 7 days: confirmation of receipt of the message to the informant (if not anonymously).
T + 30 days: preliminary conclusion (scope, investigation plan).
T + 90 days: final response/interim report for complex cases (with justification for extension).
P0 incidents (threat to life/safety, critical leak): immediate response, escalation within 2 hours.

7) Process (end-to-end flow)

1. Sending a message → assigning a unique ID, security PIN for anonymous.
2. Triage and classification (HR/Legal/GRC): risk, conflict of interest, need to preserve evidence.
3. Assign an independent team (see RACI).
4. Collection/preservation of evidence: logs, correspondence, IDS/EDR artifacts, financial documents (with a storage chain).
5. Interviews and analysis (minimizing whistleblower identity disclosure).
6. Conclusions and recommendations: disciplinary measures, control improvements, notifications to regulators (if required).
7. Fidbek to the informant: status and overall results without prejudice to the investigation/secrecy.
8. Monitoring repression: post-control 6-12 months.

8) RACI (roles and responsibilities)

StageR (performer)A (approves)C (consulting)I (informed)
Intake/triageWhistleblowing OfficerHead of ComplianceLegal, HR, SecurityBoard/Audit Com.
Conservation of evidenceSecOps/Legal HoldCISO/GCIT, Finance
InvestigationInternal InvestigationsGC/ComplianceHR, SecOps, FinanceBoard
Final measuresHR/ComplianceCEO/BoardLegalInformant
Post-monitoringHR/ManagerComplianceDPOAudit Com.

9) Protecting whistleblowers

Prohibition of repression: is fixed in labor documents/code.

Confidentiality: personal data and context are disclosed on the principle of "strictly necessary to know."

Schedule translation/modification on request of informant to reduce pressure.
Paid leave/support (if the situation is highly toxic).
Legal aid (in serious cases - compensation for basic expenses).
KPI symptoms monitoring: sudden deterioration of grades, bonus block, transfer to "penalty" shifts.

10) Anonymity: Boundaries and Expectations

Anonymous messages are accepted, but restrictions need to be honestly explained: communication is more difficult, the risk of misunderstandings. Support two-way channel (ID + PIN) for refinements. Do not try to de-anonymize - this undermines trust and may violate the law.

11) Relationship with other policies

Code of Ethics and Conduct

Anti-corruption and gift policy

AML/KYC/Sanctions

Information Security and Privacy (GDPR/PDPA/LGPD)

Occupational Health and H&S

Harassment and anti-discrimination policy

12) Data and privacy

Keep only the minimum necessary, separate the identity of the informant from the case materials.
Legal basis of processing: legitimate interest/legal duty.
Shelf life: according to local requirements (usually 3-6 years) or until the end of disputes.
Security: separate safe/keys, restricted access, audit requests.

13) External messages and regulators

The policy should recognize the right of the informant to apply directly to the competent authorities (regulators, ombudsmen, law enforcement officers), especially if internal channels are unreliable or interests conflict. The company undertakes not to obstruct or prosecute for this.

14) Matrix of categories and priorities

CategoryExamplesLevelFirst actions
Critical (P0)Threat to life, major PII leak, C-level corruptionMaximumSystem isolation, legal hold, board/regulator notification
High (P1)Systemic discrimination/harassment, sanctions violationsHighIndependent team, communications plan, whistleblower protection
Medium (P2)Conflict of interest, local violations of proceduresAverageInterviews, corrective actions, training
Low (P3)Errors without malice, isolated incidentsLowCoaching, process improvement

15) Performance metrics (dashboard)

Funnel: → received → confirmed → closed.
Average triage/closure time by priority.
Proportion of cases resulting in corrective action.
NPS/channel trust (anonymous poll).
Safety index: no complaints of repression, no "strange" personnel decisions after reports.
Training coverage and frequency.

16) Training and Communications

Annual mandatory training (cases, simulations).
Posters/landing pages with QR channel codes.
Cross-cutting examples of "how to": letters, correspondence, reporting.
Employee report: aggregated statistics and cases without personalities.

17) Interaction with suppliers/affiliates

In contracts: the obligation to have/maintain a channel of informants, to recognize the right to contact us directly, the prohibition of repression.
"Right to audit" and duty to notify of material incidents within X hours.
Common repository of ethical standards and contact points.

18) Template provisions (draft wording)

Prohibition of repression:
  • "The company does not allow any form of reprisal against individuals who reported alleged violations in good faith. Any actions that have the nature of pressure will entail disciplinary measures up to and including dismissal."
Privacy:
  • "Information about the identity of the whistleblower and details of the communication is handled confidentially and disclosed only when strictly necessary or as required by law."
Investigation independence:
  • "The investigation is being conducted by an authorised independent team; persons with a potential conflict of interest shall not be admitted to it."
SLA:
  • "Confirmation - 7 days; preliminary response - 30 days; total - 90 days (or interim report with justification of extension). "

(Adapt to local law/contracts before use.)

19) Integration with iGaming risks

Bundle with Responsible Gaming (abuse of VIP programs, self-exclusion bypasses).
Control of game providers (interference with RTP, quick fixes outside the regulations).
Marketing/affiliates: false promises, "black" leadogeneration practices.
Payments: circumvention of sanctions/AML, "gray" PSP, risky on/off-ramp.

20) Implementation checklist

1. Assign a Whistleblowing Officer and a backup reporting line to the board.
2. Select and start protected channels (external operator recommended).
3. Approve policy, RACI, SLA, message form.
4. Set up legal hold and evidence preservation procedures.
5. Conduct kick-off training + annual refreshing modules.
6. Include prohibition of repression in employment contracts and code.
7. Launch dashboard metrics and quarterly board reviews.
8. Assess risks to key suppliers and include commitments in contracts.
9. Organize a channel trust survey every 6-12 months.
10. Conduct a table-top test incident with board and key functions.

Conclusion

Whistleblower work policy is not just a "leave complaint" channel. This is an ecosystem of trust: secure channels, clear roles, independent investigation, zero tolerance for repression and regular reporting to the board. Formalized SLAs, training and integration with risk management make it an effective tool for preventing violations and strengthen the company's ethical culture.

Contact

Get in Touch

Reach out with any questions or support needs.We are always ready to help!

Telegram
@Gamble_GC
Start Integration

Email is required. Telegram or WhatsApp — optional.

Your Name optional
Email optional
Subject optional
Message optional
Telegram optional
@
If you include Telegram — we will reply there as well, in addition to Email.
WhatsApp optional
Format: +country code and number (e.g., +380XXXXXXXXX).

By clicking this button, you agree to data processing.